Bug#850007: libvncserver: CVE-2016-9941

2017-01-03 Thread Peter Spiess-Knafl
Hi Salvatore! I prepared the package containing the fixes for both CVE's on git: https://anonscm.debian.org/cgit/collab-maint/libvncserver.git/tag/?h=debian/0.9.9%2bdfsg2-6.1%2bdeb8u2 Can you upload them? Greetings, Peter On 01/03/2017 07:12 AM, Salvatore Bonaccorso wrote: > Source: libvncserv

Bug#850007: libvncserver: CVE-2016-9941

2017-01-02 Thread Salvatore Bonaccorso
Source: libvncserver Version: 0.9.10+dfsg-3 Severity: grave Tags: upstream security patch Justification: user security hole Hi, the following vulnerability was published for libvncserver. CVE-2016-9941[0]: | Heap-based buffer overflow in rfbproto.c in LibVNCClient in | LibVNCServer before 0.9.11